ComboFix 08-06-01.6 - MONA 06/03/2008 12:09:32.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1256.1.1033.18.222 [GMT 3:00]
Running from: C:\Documents and Settings\MONA\My Documents\Downloads\Programs\لأصلاح هاردسكي\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-05-03 to 2008-06-03 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-03 09:16 981,024 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-06-03 09:16 24,346,144 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-06-03 09:14 92,996 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-06-03 09:14 327,116 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-06-03 01:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-06-03 01:06 --------- d-----w C:\Documents and Settings\MONA\Application Data\DMCache
2008-06-02 20:03 --------- d-----w C:\Program Files\KYE
2008-06-02 20:03 --------- d-----w C:\Program Files\Common Files\snpstd
2008-05-31 13:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Babylon
2008-05-30 11:52 88,774 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-05-29 03:26 96,966 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-05-29 03:26 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-05-28 19:16 --------- d-----w C:\Documents and Settings\MONA\Application Data\uTorrent
2008-05-26 00:37 --------- d-----w C:\Documents and Settings\MONA\Application Data\Babylon
2008-05-24 00:02 --------- d-----w C:\Documents and Settings\MONA\Application Data\AdobeUM
2008-05-12 20:16 --------- d-----w C:\Documents and Settings\MONA\Application Data\Image Zone Express
2008-05-12 08:57 --------- d-----w C:\Program Files\Hewlett-Packard
2008-05-01 00:38 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-01 00:36 --------- d-----w C:\Program Files\Veoh Networks
2008-04-30 10:40 --------- d-----w C:\Program Files\AL_EJTEMA3YAH-EQ
2008-04-25 22:10 --------- d-----w C:\Program Files\Registry Compressor
2008-04-24 17:42 --------- d-----w C:\Documents and Settings\MONA\Application Data\Printer Info Cache
2008-04-24 17:28 --------- d-----w C:\Documents and Settings\MONA\Application Data\HP
2008-04-24 17:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\WEBREG
2008-04-24 17:24 --------- d-----w C:\Program Files\HP
2008-04-24 17:24 --------- d-----w C:\Program Files\Common Files\HP
2008-04-24 17:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2008-04-24 17:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
2008-04-24 17:21 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard
2008-04-24 17:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-04-12 05:19 --------- d-----w C:\Program Files\Babylon
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{b212e734-666c-4bca-b481-2732d66e7b50}]
04/30/2008 01:41 PM 1470488 --a------ C:\Program Files\AL_EJTEMA3YAH-EQ\tbAL_0.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{B212E734-666C-4BCA-B481-2732D66E7B50}"= "C:\Program Files\AL_EJTEMA3YAH-EQ\tbAL_0.dll" [04/30/2008 01:41 PM 1470488]
"{965B54B0-71E0-4611-8DE7-F73FA0B20E26}"= "C:\Program Files\Babylon\Babylon Toolbar\BabylonIEToolBar.dll" [02/27/2008 11:18 AM 267488]
[HKEY_CLASSES_ROOT\clsid\{b212e734-666c-4bca-b481-2732d66e7b50}]
[HKEY_CLASSES_ROOT\clsid\{965b54b0-71e0-4611-8de7-f73fa0b20e26}]
[HKEY_CLASSES_ROOT\BabylonTBLib.BabylonTB.1]
[HKEY_CLASSES_ROOT\TypeLib\{162484B8-B114-453f-A344-C0B24B0F1D99}]
[HKEY_CLASSES_ROOT\BabylonTBLib.BabylonTB]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{B212E734-666C-4BCA-B481-2732D66E7B50}"= C:\Program Files\AL_EJTEMA3YAH-EQ\tbAL_0.dll [04/30/2008 01:41 PM 1470488]
[HKEY_CLASSES_ROOT\clsid\{b212e734-666c-4bca-b481-2732d66e7b50}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [04/11/2005 02:26 PM 65536]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 04:00 PM 15360]
"NCLaunch"="C:\WINDOWS\NCLAUNCH.EXe" [11/10/2007 05:07 PM 40960]
"IDMan"="C:\Documents and Settings\MONA\My Documents\برمجيات\mambo_portable_idm_5.11_build_2\quyanhnguyen\Internet Download Manager\IDMan.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [11/28/2005 11:55 PM 98304]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [11/28/2005 11:52 PM 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [11/28/2005 11:55 PM 118784]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [12/17/2005 02:32 AM 761945]
"RTHDCPL"="RTHDCPL.EXE" [12/10/2005 01:49 AM 15691264 C:\WINDOWS\RTHDCPL.exe]
"AGRSMMSG"="AGRSMMSG.exe" [10/15/2005 04:29 PM 88203 C:\WINDOWS\agrsmmsg.exe]
"THotkey"="C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [01/05/2006 05:02 PM 352256]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe" [11/03/2007 04:50 AM 6731312]
"TPSMain"="TPSMain.exe" [08/03/2005 05:26 PM 266240 C:\WINDOWS\system32\TPSMain.exe]
"NDSTray.exe"="NDSTray.exe" []
"Tvs"="C:\Program Files\TOSHIBA\Tvs\TvsTray.exe" [11/30/2005 03:25 PM 73728]
"SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [05/12/2005 01:31 PM 118784]
"TFncKy"="TFncKy.exe" []
"TDispVol"="TDispVol.exe" [03/11/2005 06:03 PM 73728 C:\WINDOWS\system32\TDispVol.exe]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [10/06/2005 08:20 AM 122940]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [12/05/2005 12:37 PM 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [11/28/2005 11:41 AM 602182]
"CFSServ.exe"="CFSServ.exe" []
"snpstd"="C:\WINDOWS\vsnpstd.exe" [06/10/2004 01:48 PM 286720]
"zyz1"="c:\zyz_auto_killer\run2.exe" [ ]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [06/28/2007 12:51 PM 218376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 04:00 PM 15360]
C:\Documents and Settings\MONA\Start Menu\Programs\Startup\
Ela-Salaty.lnk - C:\Program Files\Ela-Salaty\Salaty.exe [2007-03-05 03:33:19 5205504]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2005-12-07 17:01:32 1744896]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"NoFolderOptions"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"= 0 (0x0)
"NoDispScrSavPage"= 0 (0x0)
"NoDispSettingsPage"= 0 (0x0)
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"NoFolderOptions"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoUserNameInStartMenu"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoClose"= 0 (0x0)
"NoFind"= 0 (0x0)
"NoRun"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
"IDMan"=C:\Documents and Settings\MONA\My Documents\برمجيات\mambo_portable_idm_5.11_build_2\quyanhnguyen\Internet Download Manager\IDMan.exe /onboot
"uTorrent"="C:\Program Files\uTorrent\utorrent.exe"
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"googletalk"=C:\Program Files\Google\Google Talk\googletalk.exe /autostart
"StormCodec_Helper"="C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
"Babylon Client"=C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe [08/04/2004 04:00 PM]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [04/04/2007 02:58 PM]
R3 tosrfec;Bluetooth ACPI from TOSHIBA;C:\WINDOWS\system32\DRIVERS\tosrfec.sys [09/09/2005 05:47 PM]
S3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [06/08/2007 09:52 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{36badc15-ea2e-11dc-819a-0013026808e7}]
\Shell\AutoRun\command - E:\d.cmd
\Shell\explore\Command - E:\d.cmd
\Shell\open\Command - E:\d.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{59a110d7-903b-11dc-a4c5-0013026808e7}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL exiplorer.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-06-03 12:17:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\Toshiba\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Toshiba\ConfigFree\CFSServ.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Documents and Settings\MONA\My Documents\C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
C:\Documents and Settings\MONA\My Documents\C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
.
**************************************************************************
.
Completion time: 06/03/2008 12:27:03 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-03 09:26:51
Pre-Run: 38,548,144,128 bytes free
Post-Run: 38,560,845,824 bytes free
199 --- E O F --- 2008-05-28 00:02:45